Privacy Policy
Last updated: 2026. 07. 03. 오전 09:43Version history →
Introduction and Who We Are
This Privacy Policy explains how Vifork (바이포크), the company that operates the Collabby service at collabby.ai (referred to here as "Collabby," "we," "us," or "our"), collects, uses, shares, and protects personal data in connection with your use of our service. Vifork is the data controller responsible for your personal data.
Collabby is an AI "vibe coding" platform that lets you build, run, publish, fork, and collaborate on web applications by chatting with AI models. Because our service is delivered globally from infrastructure operated by third parties in the United States, this policy describes cross-border processing and includes regional sections for the European Economic Area (EEA), the United Kingdom, California, and Brazil at the end.
This is the English-language master version of our global Privacy Policy. Users in the Republic of Korea are additionally covered by our separate Korean-language 개인정보처리방침(Privacy Policy), prepared under the Personal Information Protection Act (PIPA), which shares the same subprocessor register described below. Where a provision of this policy conflicts with a specific agreement we have with you, the term more protective of you as a data subject applies.
Effective date: 2026-07-03. We keep prior versions of this policy accessible and will re-publish it with a new effective date when we make material changes (see "Changes to This Policy").
Company details, including our business registration number and mail-order sales license number, are shown in the site footer under 사업자정보(business information) and are also available on request.
Personal Data We Collect
We collect the following categories of personal data, organized by how they arise during your use of the service.
Account and identity data
When you register or sign in, we collect your email address, a hashed (not plain-text) password, your display name, and, if you use social login, the identifier returned by the provider (Google or X). For X (Twitter) sign-in where no verified email is supplied by the provider, we may generate a synthetic email address to identify your account. If you enable two-factor authentication (2FA), we store your TOTP secret and recovery codes as encrypted authentication data (this is credential data, not a special category of data).
Service and content data
When you use the app builder and related features, we process the prompts you enter, the code and applications the AI generates, your conversation history, and, if you use the voice mode, your voice audio. We also process files and images you upload or that are generated for you, and metadata about your projects, apps, versions, submissions, and gallery activity. Your prompts, files, and published apps may themselves contain personal data about you or third parties; you are responsible for the content you submit.
Payment and transaction data
We process payment metadata such as the buyer email address, order and subscription identifiers, plan and credit balances, invoices, and refund/chargeback records. Card and bank details are collected directly by our Merchant of Record, Lemon Squeezy, on its own hosted checkout; we do not receive or store your full card number.
Automatically collected data
When you access the service, we automatically collect access logs, IP address, device and browser signals, cookie identifiers, bot-protection signals (via Cloudflare Turnstile), and internal audit-log records of security-relevant actions.
Data your published apps collect ("VibeRecord")
Applications you build and publish on Collabby may themselves collect personal data from their own end-users, which is stored on our infrastructure ("VibeRecord" and related free-form storage). For this end-user data our role is determined by the facts of the processing; given that Collabby fixes essential means of the storage, we may act as a joint controller or under a data-processing arrangement with you rather than as a mere processor. You remain responsible for your app's own privacy notice and lawful basis toward its end-users.
We collect this data through your direct input during registration and use of the service, through social-login callbacks, and through automatic collection tools such as cookies and server logs.
Purposes and Legal Bases
We process personal data for the purposes below. For users in the EEA and the UK, each purpose relies on a specific legal basis under the GDPR / UK GDPR, identified here. We do not rely on a single blanket "consent" basis for everything.
Providing the service (Contract — Art. 6(1)(b))
We process account, content, and payment data to create and manage your account, authenticate you, deliver the AI app-building, running, publishing, forking, and collaboration features, process your credits and subscriptions, and provide customer support. This processing is necessary to perform our contract with you.
Marketing and non-essential cookies (Consent — Art. 6(1)(a))
Where required, we rely on your consent for optional marketing emails and for non-essential cookies and analytics (including Google Analytics 4). You may withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
Security, fraud prevention, and product improvement (Legitimate interests — Art. 6(1)(f))
We process access logs, IP addresses, bot-protection signals, and usage data to keep the service secure, prevent fraud and abuse, enforce our terms, debug and improve the product, and understand aggregate usage. We rely on our legitimate interests and those of our users, balanced against your rights; you may object to this processing as described in "Your Rights."
Legal compliance (Legal obligation — Art. 6(1)(c))
We retain transaction, payment, and consumer-dispute records and issue required disclosures to comply with tax, accounting, and consumer-protection laws, including the Korean Act on Consumer Protection in Electronic Commerce.
How We Share Data and Subprocessors
We do not sell your personal data. We share personal data with the service providers ("subprocessors") listed below, which process it on our behalf to run the service, and with independent recipients where noted. All of these providers are located in the United States; there is no domestic (Korean) vendor in our data plane. Each provider is engaged under a data-processing agreement (DPA) requiring appropriate safeguards, and we maintain and update this list.
Supabase Inc. (United States)
Purpose: Managed Postgres database — our primary application data store. Data: Email, hashed password, social-login identifiers, display name, app and project data, credit/subscription/payment metadata, encrypted 2FA/TOTP secrets, and stored prompts and conversations. Transfer safeguard: EU→US Standard Contractual Clauses (SCCs) Module 2 plus a transfer impact assessment, or the EU-US Data Privacy Framework (DPF) where the importer is currently certified; UK IDTA/Addendum; DPA with security measures.
Vercel Inc. (United States)
Purpose: Production hosting, serverless compute, and edge delivery of the application. Data: Request data, IP address, server and access logs, and session/authentication cookie data. Transfer safeguard: SCCs Module 2 plus transfer impact assessment / UK IDTA (and the Swiss-US DPF for Swiss users); DPA.
Anthropic PBC (United States)
Purpose: Claude AI — text and code generation for the app builder. Data: Prompts, generated code, and conversation content. Transfer safeguard: SCCs / DPF plus transfer impact assessment; DPA. Under Anthropic's commercial API terms, inputs are not used to train foundation models by default; standard input/output retention is short (currently a 7-day window under Anthropic's policy from 2025-09-14), with a zero-data-retention option.
OpenAI OpCo, LLC (United States)
Purpose: GPT — text and code generation and the gpt-realtime voice assistant. Data: Prompts, generated code, and, for voice mode, audio (transmitted from your device directly to OpenAI over raw WebRTC). Transfer safeguard: SCCs / DPF plus transfer impact assessment; DPA. Under OpenAI's commercial API terms, inputs are not used to train foundation models by default; abuse-monitoring logs are retained for a limited period (up to about 30 days), although standard API logs may be retained longer where a valid legal preservation order applies, unless a zero-data-retention arrangement is in place.
Google LLC — Gemini API (United States)
Purpose: Gemini — text and code generation for the Free tier. Data: Prompts and generated code. Transfer safeguard: SCCs / DPF plus transfer impact assessment. Important caveat: the Free tier is served via Google's consumer Generative Language API. Outside the EEA, Switzerland, and the UK, Google may use content submitted through this API to provide, improve, and develop its products and services, and human reviewers may read the content. This training/review use is a Google purpose and is not covered by an ordinary processor arrangement. Paid AI tiers use Anthropic and OpenAI as described above.
Google LLC — Google Analytics 4 (United States)
Purpose: Web analytics and usage measurement. Data: Pseudonymous usage data, cookie/device identifiers, and IP address. Transfer safeguard: SCCs / DPF plus transfer impact assessment. Google Analytics loads only after you accept non-essential cookies in our consent banner; Google acts as an analytics provider for this purpose. You can decline by refusing cookie consent.
Tavily (United States)
Purpose: Web-search retrieval for AI features. Data: Search queries derived from your input. Transfer safeguard: SCCs / DPF plus transfer impact assessment; DPA.
Cloudflare, Inc. (United States)
Purpose: R2 object storage (uploaded files, AI-generated images, and submissions) and Turnstile (bot-protection CAPTCHA at signup). Data: Uploaded and generated files and images and submissions; for Turnstile, IP address and browser signals collected at signup. Transfer safeguard: SCCs / DPF plus transfer impact assessment; DPA.
Resend (United States)
Purpose: Transactional email delivery (verification, notifications, and payment emails). Data: Email address and message metadata. Transfer safeguard: SCCs / DPF plus transfer impact assessment; DPA.
Upstash (United States)
Purpose: Rate limiting (Redis REST) and resumable-stream sessions for the app builder. Data: Email and IP (as rate-limit keys) and in-progress stream content (conversation and code being generated). Transfer safeguard: SCCs / DPF plus transfer impact assessment; DPA.
Lemon Squeezy, LLC (United States)
Purpose: Merchant of Record — payment processing, tax/VAT handling, and refunds/chargebacks. Data: Buyer email, order and subscription identifiers, and payment metadata (card data is collected directly by Lemon Squeezy on its hosted checkout). Transfer safeguard: As Merchant of Record, Lemon Squeezy is an independent controller that collects payer information for its own legal and tax purposes under its own privacy policy; it is not a mere processor acting on our behalf. Your card statement may show "Lemon Squeezy." We remain the service provider and the seller responsible for consumer rights, including cancellation, withdrawal, refunds, and complaints. We retain only a masked snapshot of the buyer email for our transaction records.
International Data Transfers
Collabby is operated from the Republic of Korea, but all of the subprocessors above are located in the United States, so your personal data is hosted and processed in the United States. Transfers of personal data out of the EEA, the UK, or Switzerland to the United States are made under appropriate safeguards: the EU Standard Contractual Clauses (Module 2) together with a transfer impact assessment, or the EU-US Data Privacy Framework where the importer is currently certified; the UK International Data Transfer Agreement or Addendum (or the UK-US data bridge where available) for UK transfers; and the Swiss addendum for Swiss users. Where legally permitted, we may also rely on your explicit consent for a specific transfer. You may request a copy of the relevant safeguards using the contact details below.
Data Retention and Deletion
We keep personal data only for as long as necessary for the purposes described in this policy, and then delete or anonymize it. Retention periods depend on the type of data and applicable law.
Where the law requires it, we retain certain records for statutory minimum periods. Under Korea's Act on Consumer Protection in Electronic Commerce, for example, records of contracts and withdrawal of subscription are kept for 5 years, records of payment and supply of goods for 5 years, records of consumer complaints and dispute resolution for 3 years, and records of labeling and advertising for 6 months. Access logs are retained for at least the statutory minimum (one year, or two years where higher thresholds for sensitive or unique-identifier processing apply).
When you delete your account, we delete or anonymize your personal data without undue delay, in principle within 30 days, subject to the honest exceptions below:
Forked and publicly shared content. If you chose to make an app public or allow it to be remixed, and another user has forked it, that fork becomes an independent copy owned by that third party. Such copies — which may embed prompts, code, or files from your original — are not within your account and may persist after your account is deleted. We cannot guarantee their deletion.
Statutory transaction and payment records. Transaction and payment records that we are legally required to keep are separated and masked (for example, we retain only a masked buyer-email snapshot) and are stored for the applicable statutory period before being deleted.
Backups and logs. Residual copies may remain in secure backups and logs for a limited period until they are overwritten or purged on our defined retention schedule, and copies held by subprocessors are deleted in accordance with their agreements.
Your Rights
Subject to applicable law, you have rights over your personal data, including the rights to access it, to have inaccurate data corrected, to request its deletion (erasure), to obtain a copy of certain data in a portable, machine-readable format, to restrict or object to certain processing, and to withdraw consent where processing is based on consent. You may also request access to and a copy of your transaction records.
To exercise any of these rights, contact us at privacy@collabby.ai or through our Data Protection Officer (see "Contact and Complaints"). We will verify your identity (or the authority of a legal representative) before acting, and we will respond within the timeframe required by applicable law (for EEA/UK requests, generally within one month). We honor the statutory rights described above; where a request implicates the fork or statutory-retention exceptions explained under "Data Retention and Deletion," or another legal exemption, we will tell you and explain the reason. Under applicable law you may exercise these rights, and we will give effect to them, even where a fully automated self-service tool is not yet available for a particular request.
Children
Our service is intended for adults and is not directed to children. Consistent with a minimum-age posture of 18 or the age of majority in your jurisdiction (in Korea, 19 years or older; purchases may be made only by users who have reached the age of majority), we do not knowingly allow underage registration and do not knowingly collect personal data from children under 14 in Korea, under 13 in the United States (COPPA), or under the applicable digital-consent age in the EEA and the UK (which ranges from 13 to 16 depending on the country).
For users in Korea, we provide an affirmative disclosure that a minor may cancel a contract entered into without the consent of a legal representative, as provided by law. Where processing of a child's data on a consent basis would require it, that consent must be given and verified by the child's legal representative.
If we become aware that we have collected personal data from a child below the applicable age without the required legal-representative consent, we will delete the data without undue delay and close the account. A parent or legal representative may contact us at privacy@collabby.ai to review or request deletion of a child's personal data.
Cookies and Analytics
We use cookies and similar technologies. Strictly necessary cookies (for example, session and authentication cookies) are required to operate the service and cannot be switched off. Non-essential cookies — principally Google Analytics 4 for usage measurement — load only after you accept them in our cookie-consent banner. You can refuse or withdraw consent to non-essential cookies at any time through the banner or your browser settings; for visitors in the EEA and the UK, non-essential trackers do not fire before you opt in. We also use Cloudflare Turnstile at signup to detect bots, which sends your IP address and browser signals to Cloudflare in the United States.
AI Processing, Training, and Retention
When you use AI features, your prompts, generated code, conversation content, and (for voice mode) audio are processed by the AI providers listed under "How We Share Data and Subprocessors." Voice audio in gpt-realtime mode is transmitted from your device directly to OpenAI over raw WebRTC.
Training and retention practices differ by provider, and we describe them factually rather than with a single blanket claim:
Under Anthropic's and OpenAI's commercial API terms, your inputs are not used to train their foundation models by default, and input/output retention is limited (as described in the Anthropic and OpenAI entries above).
For the Free tier served by Google's consumer Gemini API, outside the EEA, Switzerland, and the UK, Google may use content to provide and improve its products and services, and human reviewers may read it. We therefore do not represent that the Free/Gemini path is training-free.
Collabby does not use Your Content to train its own models.
If you bring your own API key (BYOK), your data is processed under your own account and the terms of that provider, which may permit training. Where AI-generated output is required to be labeled as AI-generated under applicable law, we will provide such labeling as required by those laws.
Security Measures
We take technical and organizational measures to protect personal data, appropriate to the risk. These include: encryption of credentials and sensitive fields (passwords are stored as hashes, and 2FA/TOTP secrets and recovery codes are sealed with AES-256-GCM encryption); access control and least-privilege permissions; retention and review of access logs; encryption of data in transit; and data-processing agreements with our subprocessors that require them to apply appropriate safeguards. No method of transmission or storage is completely secure, but we work to protect your data and to detect and respond to incidents.
Breach Notification
If a personal-data breach occurs, we will notify affected data subjects and report to the competent supervisory authority within the timeframes required by applicable law (for example, under Korea's PIPA, notice to affected data subjects without undue delay and generally within 72 hours, with reporting to the authority where thresholds such as 1,000 or more affected data subjects, sensitive or unique-identifier data, or unauthorized external access are met; and, under the GDPR, notice to the lead supervisory authority within 72 hours and to affected data subjects where the breach is likely to result in high risk). We flow breach-notification duties down to our subprocessors so that we can meet these timelines.
Changes to This Policy
We may update this policy from time to time. When we make material changes, we will re-publish it with a new effective date and keep prior versions accessible. Where we change the recipients, items, or retention periods for cross-border transfers, we will re-publish the relevant disclosures. We encourage you to review this policy periodically.
Region-Specific Rights — EEA and United Kingdom
If you are in the EEA or the UK, the GDPR / UK GDPR apply to our processing of your personal data, and the legal bases and rights described above apply to you. Our EEA representative under Article 27 GDPR and our UK representative under Article 27 UK GDPR will be designated (appointment pending); once named, their contact details will appear here and in the site footer. Where required for content-moderation and takedown matters, our EU legal representative will likewise be designated.
International transfers of your data to the United States are made under the safeguards described in "International Data Transfers." You may exercise your rights of access, rectification, erasure, restriction, portability, and objection, and withdraw consent, by contacting privacy@collabby.ai; we will respond within one month as required by the GDPR. You also have the right to lodge a complaint with your local data protection supervisory authority (in the UK, the Information Commissioner's Office).
Region-Specific Rights — California
This section supplements the policy for California residents under the CCPA/CPRA. The categories of personal information we collect, the purposes for which we use them, and the parties with whom we share them are described above and serve as our notice at collection. We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising as those terms are defined under California law. We honor opt-out preference signals such as Global Privacy Control (GPC) as a valid request to opt out of any sale or sharing.
California residents have the rights to know and access the personal information we have collected, to request its deletion, to request correction, and to be free from discrimination for exercising these rights. To the extent we process sensitive personal information, you may request that we limit its use to permitted purposes. You may submit requests at privacy@collabby.ai and may use an authorized agent as permitted by law; we will verify your request before responding.
Region-Specific Rights — Brazil
If you are in Brazil, the Lei Geral de Proteção de Dados (LGPD) applies. You have the rights to confirmation and access, correction, anonymization or deletion of unnecessary data, portability, information about sharing, and to withdraw consent, among others. Our data protection officer (encarregado) can be reached at privacy@collabby.ai. You may also contact the Brazilian data protection authority (ANPD).
Contact and Complaints
Controller: Vifork (바이포크), operator of Collabby (collabby.ai). Our business registration number, mail-order sales license number, and other company details are displayed in the site footer under 사업자정보 and are available on request.
General and privacy contact: support@collabby.ai.
Data Protection Officer / 개인정보 보호책임자: Inyoung An (안인영), Representative — privacy@collabby.ai.
For users in Korea, you may also seek help from the Personal Information Dispute Mediation Committee (개인정보분쟁조정위원회, 1833-6972), the Personal Information Infringement Report Center (개인정보침해신고센터, 118), or the cyber-investigation units of the Supreme Prosecutors' Office and the National Police Agency. Users in the EEA or the UK may lodge a complaint with their local supervisory authority, and users in Brazil with the ANPD.
Company 바이포크 (Vifork)Representative 안인영 (Inyoung An)Business Reg. No. 139-06-21251Mail-Order Sales Reg. 제2026-서울동대문-1223호Email support@collabby.aiHosting Vercel Inc. / Supabase Inc.Payments (MoR) Lemon Squeezy, LLCVerify business info ↗